CVE-2008-1702
e107 my_gallery 2.3 - Absolute Path Traversal via dload.php file Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1702. PoCs published by Jerome Athias.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file download vulnerability in the My_Gallery plugin for e107. The vulnerability arises from insufficient input validation in the 'file' parameter of dload.php, allowing attackers to download sensitive files from the server.
Description
Absolute path traversal vulnerability in dload.php in the my_gallery 2.3 plugin for e107 allows remote attackers to obtain sensitive information via a full pathname in the file parameter. NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit demonstrates an arbitrary file download vulnerability in the My_Gallery plugin for e107. The vulnerability arises from insufficient input validation in the 'file' parameter of dload.php, allowing attackers to download sensitive files from the server.